nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #206

You have stored company approved compute images in a single Google Cloud project that is used as an image repository. This project is protected with VPC Service Controls and exists in the perimeter…

The correct answer is B. 1. Update the perimeter. VPC Service Controls perimeters block access to and from external resources by default. To allow an external Google Cloud organization's disk image to be accessed from within the perimeter, you must update the service perimeter's ingress/egress rules to explicitly permit that…

Submitted by parkjh· Apr 18, 2026Configuring access within a cloud solution environment

Question

You have stored company approved compute images in a single Google Cloud project that is used as an image repository. This project is protected with VPC Service Controls and exists in the perimeter along with other projects in your organization. This lets other projects deploy images from the image repository project. A team requires deploying a third-party disk image that is stored in an external Google Cloud organization. You need to grant read access to the disk image so that it can be deployed into the perimeter. What should you do?

Options

  • AAllow the external project by using the organizational policy,
  • B
    1. Update the perimeter.
  • C
    1. Update the perimeter.
  • D
    1. Update the perimeter.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    81% (26)
  • C
    9% (3)
  • D
    6% (2)

Explanation

VPC Service Controls perimeters block access to and from external resources by default. To allow an external Google Cloud organization's disk image to be accessed from within the perimeter, you must update the service perimeter's ingress/egress rules to explicitly permit that external resource. This involves adding an ingress rule that allows the specific external project or image resource through the perimeter boundary. Option A (organizational policy) can restrict which images are used but does not override VPC Service Controls boundaries. Options C and D are described similarly to B in truncated form, but the canonical approach is updating the perimeter ingress policy to allow the external resource - which corresponds to answer B.

Topics

#VPC Service Controls#Perimeters#Cross-organization access#Image deployment security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice